Skip to content

Releases: CyberDefenseInstitute/CDIR-A

2306

23 Jun 02:06
Compare
Choose a tag to compare

add HKCU\Environment\UserInitMprLogonScript to regruns check target

2207

05 Jul 23:25
Compare
Choose a tag to compare

fix usnjrnl encoding issue

2010

08 Oct 02:59
Compare
Choose a tag to compare
  • prefetch.py
    • fixed interpretation of run count information
  • amcache.py
    • fixed bug so as to correctly write the header when ingesting multiple target hosts
    • added "--no-header-inventory" option
  • upgrade third party tools
    • BrowsingHistoryView.exe: 2.25 to 2.41
    • NetworkUsageView.exe: 1.13 to 1.20

2001

01 Jan 06:22
Compare
Choose a tag to compare
  • prefetch.py, amcache.py, usnjrnl.py, parserutility.py, PyWMIPersistenceFinder.py

    • modified to run on python3.
      errors may occur on python2.
  • prefetch.exe, amcache.exe, usnjrnl.exe, parserutility.exe, PyWMIPersistenceFinder.exe

    • replaced with the ones from the modified *.py above.

1910

10 Oct 03:56
Compare
Choose a tag to compare
  • prefetch.exe

    • add functionality to parse the prefetch file in ADS.
    • fix bug so as to correctly parse the run count contained in prefetch files of Windows 10 version 1903.
  • upgrade third party tools

    • Secure2Csv64.exev: 1.0.0.8 to 1.0.0.9
    • NetworkUsageView.exe: 1.12 to 1.13
    • BrowsingHistoryView.exe: 2.17 to 2.25

1902

12 Feb 05:08
Compare
Choose a tag to compare
  • mft.exe
    • improved handling of path name
    • fixed interpretation of size information
    • fixed processing of -e option
  • regruns.exe and shimcache.exe
    • fixed even if a hive is dirty and no transaction logs
    • workaround for handling of irregular key
  • LPSLibrary_CDI.XML
    • added a query for network status
    • splitted into two queries about sleep and clocks change
  • prefetch.exe
    • fixed processing if a prefetch file is truncated
  • added third party tools:
    • BrowsingHistoryView.exe
    • NetworkUsageView.exe
    • PyWMIPersistenceFinder.exe
    • Secure2Csv64.exe

1806

07 Jun 08:08
Compare
Choose a tag to compare
  • CDIR-C 1.3 compatible (naming rules of filename and diretory)
  • mft.exe: added securityID column
  • amcache.exe: fixed when specific key not found
  • regruns: support parsing of transaction log

1802

15 Feb 02:08
Compare
Choose a tag to compare
  • amcache.exe: updated for Windows 10 (1709) format partially
  • shimcache.exe: updated for Windows 10 (1703) format
  • mft.exe: fixed some file record shows wrong value of file size

1706

03 Jul 05:48
Compare
Choose a tag to compare
update 1706